Pith. sign in

REVIEW 1 cited by

Calibration Attacks: A Comprehensive Study of Adversarial Attacks on Model Confidence

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2401.02718 v3 pith:7SLO24PD submitted 2024-01-05 cs.LG cs.CR

classification cs.LGcs.CR
keywords attackscalibrationconfidenceadversarialcomprehensivemodelshencepotential
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

In this work, we highlight and perform a comprehensive study on calibration attacks, a form of adversarial attacks that aim to trap victim models to be heavily miscalibrated without altering their predicted labels, hence endangering the trustworthiness of the models and follow-up decision making based on their confidence. We propose four typical forms of calibration attacks: underconfidence, overconfidence, maximum miscalibration, and random confidence attacks, conducted in both black-box and white-box setups. We demonstrate that the attacks are highly effective on both convolutional and attention-based models: with a small number of queries, they seriously skew confidence without changing the predictive performance. Given the potential danger, we further investigate the effectiveness of a wide range of adversarial defence and recalibration methods, including our proposed defences specifically designed for calibration attacks to mitigate the harm. From the ECE and KS scores, we observe that there are still significant limitations in handling calibration attacks. To the best of our knowledge, this is the first dedicated study that provides a comprehensive investigation on calibration-focused attacks. We hope this study helps attract more attention to these types of attacks and hence hamper their potential serious damages. To this end, this work also provides detailed analyses to understand the characteristics of the attacks. Our code is available at https://github.com/PhenetOs/CalibrationAttack

Discussion (0). Sign in to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Towards Unveiling Predictive Uncertainty Vulnerabilities in the Context of the Right to Be Forgotten

    cs.LG 2025-08 conditional novelty 6.0 of 10

    Maliciously crafted deletion requests can make an unlearned model overconfident or underconfident on target samples while preserving its labels, across multiple uncertainty quantification methods.

Pith tools